Vulnerability Details CVE-2011-5071
Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.64 allow remote attackers to execute arbitrary SQL commands via the (1) exc[] parameter to report_marketing.php, (2) selected[] parameter to tasks.php, (3) sites[] parameter to billable_incidents.php, or (4) search_string parameter to search.php. NOTE: some of these details are obtained from third party information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 62.9%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2011-5071
-
cpe:2.3:a:sitracker:support_incident_tracker:1.8.00
-
cpe:2.3:a:sitracker:support_incident_tracker:2.8.00
-
cpe:2.3:a:sitracker:support_incident_tracker:3.00
-
cpe:2.3:a:sitracker:support_incident_tracker:3.01
-
cpe:2.3:a:sitracker:support_incident_tracker:3.02
-
cpe:2.3:a:sitracker:support_incident_tracker:3.03
-
cpe:2.3:a:sitracker:support_incident_tracker:3.03a
-
cpe:2.3:a:sitracker:support_incident_tracker:3.04a
-
cpe:2.3:a:sitracker:support_incident_tracker:3.05
-
cpe:2.3:a:sitracker:support_incident_tracker:3.06
-
cpe:2.3:a:sitracker:support_incident_tracker:3.07
-
cpe:2.3:a:sitracker:support_incident_tracker:3.21
-
cpe:2.3:a:sitracker:support_incident_tracker:3.22
-
cpe:2.3:a:sitracker:support_incident_tracker:3.22pl1
-
cpe:2.3:a:sitracker:support_incident_tracker:3.23
-
cpe:2.3:a:sitracker:support_incident_tracker:3.24
-
cpe:2.3:a:sitracker:support_incident_tracker:3.30
-
cpe:2.3:a:sitracker:support_incident_tracker:3.31
-
cpe:2.3:a:sitracker:support_incident_tracker:3.32
-
cpe:2.3:a:sitracker:support_incident_tracker:3.33
-
cpe:2.3:a:sitracker:support_incident_tracker:3.35
-
cpe:2.3:a:sitracker:support_incident_tracker:3.36
-
cpe:2.3:a:sitracker:support_incident_tracker:3.40
-
cpe:2.3:a:sitracker:support_incident_tracker:3.41
-
cpe:2.3:a:sitracker:support_incident_tracker:3.45
-
cpe:2.3:a:sitracker:support_incident_tracker:3.50
-
cpe:2.3:a:sitracker:support_incident_tracker:3.51
-
cpe:2.3:a:sitracker:support_incident_tracker:3.6
-
cpe:2.3:a:sitracker:support_incident_tracker:3.60
-
cpe:2.3:a:sitracker:support_incident_tracker:3.61
-
cpe:2.3:a:sitracker:support_incident_tracker:3.62
-
cpe:2.3:a:sitracker:support_incident_tracker:3.63